MALICIOUS — CRITICAL
sparkdex[.]io
Analysis of sparkdex.io shows a short‑lived domain that was created on February 21, 2026 and is currently taken offline.
- VirusTotal
- 6/93
- Blocklists
- 1 · ScamSniffer
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
sparkdex.io — İçerik kullanılamıyor (HTTP 502). Kanıt özeti: VirusTotal 6/93 (ADMINUSLabs, alphaMountain.ai, CyRadar, Fortinet, Seclookup); URLQuery 2 alerts; 1 external blocklist match (ScamSniffer); PhishDestroy score 72/100. Kayıt kuruluşu: TLD Registry (.io).
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
Analysis of sparkdex.io shows a short‑lived domain that was created on February 21, 2026 and is currently taken offline. The site resolves to the IP address 188.114.97.3, which belongs to the Cloudflare network (AS13335) and is geolocated in the United States. No SSL certificate is presented, indicating that the site was served over plain HTTP. The page title returned by the server is "Nur einen Moment…", a German phrase meaning "Just a moment…", but the content of the page has not been publicly examined, so the exact lure or credential‑capture mechanism remains unknown.
The domain appears on two independent phishing blocklists, PhishDestroy and ScamSniffer, and has been flagged by six of ninety‑three VirusTotal scanners, reinforcing the suspicion of malicious intent. Gridinsoft assigns the domain a trust score of zero out of one hundred, reflecting a severe lack of reputation. Registration was performed through the generic .io TLD registry, providing no additional ownership clues.
Defenders encountering traffic to sparkdex.io should block the domain at perimeter filters, enforce DNS sinkholing, and monitor for any outbound connections to the associated Cloudflare IP. Because the site is offline, immediate threat exposure is limited, but the infrastructure indicates a typical fast‑flux style phishing deployment that could be reused with new payloads. Continuous observation of the IP address and related Cloudflare ranges is advised, as attackers often recycle the same hosting assets for subsequent campaigns.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
VirusTotal Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
“Ace drainer”
PD-1767767639-sparkdex.io Recipient: abuse@nic.io Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.